Replacing CP Server Cert ; lose access to webGUI?

So my previous boss didn't see any need to replace the default cert in our iAPs, now along with some of you I'm dealing with the fallout related to the cert revocation.

I've got a new Public cert in .pem, and it has been uploaded to replace the default CA and Server certs with no problem. When I try to replace the CP Server it uploads correctly, and then I lose access to the WebGUI.

Network still online, I can SSH to the Virtual Controler, and clearing the new CP Server cert returns GUI access....what am I missing here?

There are also a number of Checksum errors that look like they are across all of the APs in this cluster. Quick research says that is probably do to the configurations not being the same on all the APs in the cluster?

Re: Replacing CP Server Cert ; lose access to webGUI?

‎10-13-201612:41 PM

Sorry I didn't follow up on this before, in the end a co-worker worked with Aruba, and the answer was that the chaining (order that the certificates in the .pem) was out of order. Worked fine for the CA and the Auth server, but it broke the CP.